Back to advisories

Critical wp2shell WordPress flaws exploited to install webshells

Critical unauthenticated RCE vulnerabilities in WordPress Core (CVE-2026-63030, CVE-2026-60137) are being actively exploited via REST API batch processing to deploy webshells and malicious plugins. All unpatched WordPress instances are at risk. Attackers are actively scanning and compromising sites to establish persistence and steal credentials.

CRITICALAdvisoryJul 23, 2026
Action required
Immediately identify all WordPress instances in your environment and verify they are patched to the latest version. Scan web logs for REST API batch requests (/wp-json/batch) and monitor for suspicious plugin installations or webshell uploads in wp-content directories.
Affected products
WordPress CoreSearchLight CyberWizSans Technology InstituteDefiant